Vulnerabilities > Loop with Unreachable Exit Condition ('Infinite Loop')

DATE CVE VULNERABILITY TITLE RISK
2017-07-18 CVE-2017-11406 Infinite Loop vulnerability in multiple products
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop.
network
low complexity
wireshark debian CWE-835
7.5
2017-07-17 CVE-2017-10986 Infinite Loop vulnerability in Freeradius
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
network
low complexity
freeradius CWE-835
7.5
2017-07-17 CVE-2017-10985 Infinite Loop vulnerability in Freeradius
An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.
network
low complexity
freeradius CWE-835
7.5
2017-07-17 CVE-2017-11338 Infinite Loop vulnerability in Exiv2 0.26
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26.
network
low complexity
exiv2 CWE-835
6.5
2017-07-11 CVE-2017-11171 Infinite Loop vulnerability in Gnome Gnome-Session 2.29.92
Bad reference counting in the context of accept_ice_connection() in gsm-xsmp-server.c in old versions of gnome-session up until version 2.29.92 allows a local attacker to establish ICE connections to gnome-session with invalid authentication data (an invalid magic cookie).
local
low complexity
gnome CWE-835
5.5
2017-07-06 CVE-2017-0685 Infinite Loop vulnerability in Google Android
A denial of service vulnerability in the Android media framework.
local
low complexity
google CWE-835
5.5
2017-06-27 CVE-2017-9222 Infinite Loop vulnerability in Audiocoding Freeware Advanced Audio Decoder 2 2.7
The mp4ff_parse_tag function in common/mp4ff/mp4meta.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
local
low complexity
audiocoding CWE-835
5.5
2017-06-16 CVE-2017-9375 Infinite Loop vulnerability in multiple products
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
local
low complexity
qemu debian CWE-835
5.5
2017-06-12 CVE-2017-9122 Infinite Loop vulnerability in Libquicktime 1.2.4
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
network
low complexity
libquicktime CWE-835
6.5
2017-06-12 CVE-2017-8871 Infinite Loop vulnerability in multiple products
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
network
low complexity
gnome opensuse CWE-835
6.5